highCVSS 7.5Vulnerability

GHSA-537c-gmf6-5ccf

pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.

Properties

ghsa_id
GHSA-537c-gmf6-5ccf
severity
high
summary
Vulnerable OpenSSL included in cryptography wheels
cvss_score
7.5
cve_id
GHSA-537c-gmf6-5ccf
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-06-15T20:12:27Z
source_url
https://github.com/advisories/GHSA-537c-gmf6-5ccf
ghsa_updated
2026-06-15T20:12:29Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]pip/cryptography

AFFECTS (1)

[Software]pip/cryptography

HAS_WEAKNESS (2)

[Weakness]Out-of-bounds Read
[Weakness]Dependency on Vulnerable Third-Party Component

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-537c-gmf6-5ccf (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal